CVE-2026-8769: vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumption
A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8769?
CVE-2026-8769 is classified as a resource consumption vulnerability.
How do I fix CVE-2026-8769?
To mitigate CVE-2026-8769, upgrade the affected package to a version higher than 3.0.97.
What versions are affected by CVE-2026-8769?
CVE-2026-8769 affects vercel ai versions up to and including 3.0.97.
What component of the software is impacted by CVE-2026-8769?
CVE-2026-8769 impacts the createJsonResponseHandler and createJsonErrorResponseHandler functions in the response-handler.ts file.
How can CVE-2026-8769 impact my application?
CVE-2026-8769 can potentially lead to resource exhaustion and degradation of service in applications utilizing the affected versions.